如何通过Python递归删除Azure Data Lake Gen1的访问控制列表(ACL)?
Recursive ACL Removal for Azure Data Lake Storage Gen1 in Python
Absolutely, you can pull off recursive ACL removal for Azure Data Lake Storage Gen1 using Python—you just need to roll your own recursion logic since there’s no out-of-the-box remove_access_control_recursive method like the one available for Gen2. Let me walk you through how to do this step-by-step:
Prerequisites
First, install the required Python packages to interact with ADLS Gen1:
pip install azure-mgmt-datalake-store azure-identity
Example Implementation
This script will recursively traverse your target directory, remove the specified ACL entry from every file and subdirectory, and update the ACLs accordingly:
from azure.identity import DefaultAzureCredential from azure.mgmt.datalake.store import DataLakeStoreAccountManagementClient def remove_acl_recursively(account_name, root_path, acl_entry): # Initialize authentication and ADLS Gen1 client credential = DefaultAzureCredential() adls_client = DataLakeStoreAccountManagementClient(credential, "<your-subscription-id>") def process_single_path(path): try: # Fetch the current ACL for the target path current_acl = adls_client.adls_store.get_access_control(account_name, path) # Filter out the ACL entry we want to remove acl_lines = [line.strip() for line in current_acl.split('\n') if line.strip()] updated_acl_lines = [line for line in acl_lines if line != acl_entry.strip()] updated_acl = '\n'.join(updated_acl_lines) # Apply the cleaned-up ACL back to the path adls_client.adls_store.set_access_control(account_name, path, updated_acl) print(f"Successfully updated ACL for: {path}") # If this is a directory, process all child files/subdirectories file_status = adls_client.adls_store.get_file_status(account_name, path) if file_status.is_directory: child_items = adls_client.adls_store.list_file_system(account_name, path) for item in child_items: # Handle root path vs subdirectories to avoid malformed paths child_path = f"{path}/{item.name}" if path != '/' else f"/{item.name}" process_single_path(child_path) except Exception as e: print(f"Failed to process {path}: {str(e)}") # Start the recursive processing from your root directory process_single_path(root_path) # Usage example if __name__ == "__main__": # Replace with your ADLS Gen1 account details ADLS_ACCOUNT = "your-adls-gen1-account-name" TARGET_DIRECTORY = "/my-parent-directory" # Specify the ACL entry to remove (add "default:" prefix for default scope entries) ACL_ENTRY_TO_REMOVE = "user:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" # For default scope: "default:user:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" remove_acl_recursively(ADLS_ACCOUNT, TARGET_DIRECTORY, ACL_ENTRY_TO_REMOVE)
Key Notes
- Manual Recursion: Since Gen1 doesn’t have a built-in recursive ACL method, we explicitly traverse every file and subdirectory to update permissions one by one.
- Permissions Check: Make sure the identity running the script has sufficient ACL permissions (at minimum,
WriteandExecuteon all paths being modified) to make changes. - ACL Entry Precision: Match the exact format of the ACL entry you want to remove. For default scope entries, include the
default:prefix (e.g.,default:user:<object-id>). - Error Resilience: The script includes basic error handling to catch issues with individual paths without stopping the entire recursive operation.
内容的提问来源于stack exchange,提问作者Ash3060
相关产品推荐
相关产品推荐

